# bugcrowd/HUNT

Repository: https://github.com/bugcrowd/HUNT
Canonical: https://ross.abutalabs.com/products/hunt
Language: Python
License: Apache-2.0
License Family: permissive
Topics: hunt, burpsuite, owasp-zap
Last push: 2026-08-26T04:21:39+00:00

## Health v2 (maintenance only)
Score: 67/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 8, longevity 100
- inputs: {"age_days": 3460, "days_push": 7, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2331, forks 433 (observed 2026-08-28T04:06:37.766973+00:00)

## What it is
HUNT Suite is a collection of Burp Suite and OWASP ZAP proxy extensions that identify common parameters vulnerable to vulnerability classes like SQL injection, SSRF, and command injection, and help organize testing methodologies. It alerts testers to suspicious parameters for manual testing rather than performing automated exploitation.

## Use cases
- find parameters in web traffic that may be vulnerable to SQL injection or SSRF
- organize my manual bug bounty testing methodology inside Burp Suite
- flag IDOR-prone parameters while proxying requests
- track which methodology steps I've completed during a pentest
- surface debug and logic parameters in HTTP requests
- assist manual testing of web app vulnerability classes in OWASP ZAP

## When to choose
- you use Burp Suite or OWASP ZAP for manual web application security testing
- you want parameter-level hints for common vulnerability classes during bug bounty hunting
- you need a structured methodology tracker inside your proxy tool

## When to avoid
- you need fully automated vulnerability scanning or exploitation
- you don't use Burp Suite or OWASP ZAP
- you need coverage for XSS, XXE, or file upload classes, which are deprecated in this tool

## Facets
- artifact type: plugin
- maturity: maintenance
- function: security, penetration-testing, vulnerability-scanning, developer-tools
- domain: security, penetration-testing, web-development, developer-tools
- platform: cross-platform, browser-extension
- tags: burpsuite, owasp-zap, bug-bounty, web-security-testing, manual-testing, proxy-extensions, jython

## Member repositories
- bugcrowd/HUNT (main) score 67

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:37.766973+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:37:58.751695+00:00, confidence not recorded.
  - readme: https://github.com/bugcrowd/HUNT (fetched 2026-08-28T04:06:37.766973+00:00, sha 1c7a5c1e3d47)
- Data as of 2026-08-30T08:39:29.467469+00:00.
